Threat actors are exploiting unpatched ManageEngine instances. CISA adds the vulnerability to its catalog and Zoho urges customers to check their deployments.
Nucleus researcher offers insight into how the vulnerability surrounding Zoho’s cloud-based ManageEngine platform was ultimately uploaded to the KEV catalog.
The Cybersecurity and Infrastructure Security Agency (CISA) has added a critical severity Java deserialization vulnerability affecting multiple Zoho ManageEngine products to its catalog of bugs exploited in the wild.